ID

VAR-201907-0310


CVE

CVE-2019-9228


TITLE

plural AudioCodes Mediant Resource management vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-006942

DESCRIPTION

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice. ** Unsettled ** This case has not been confirmed as a vulnerability. plural AudioCodes Mediant The product contains a resource management vulnerability. The vendor has disputed this vulnerability. For details, see NVD of Current Description Please Confirm. https://nvd.nist.gov/vuln/detail/CVE-2019-9228Service operation interruption (DoS) There is a possibility of being put into a state. AudioCodes Mediant 500L-MSBR and others are products of Israel's AudioCodes. AudioCodes Mediant 500L-MSBR is a 500L series integrated SOHO/SMB router. AudioCodes Mediant 500-MSBR is a 500 series integrated SOHO/SMB router. AudioCodes M800B-MSBR is an M800B series integrated SOHO/SMB router. An attacker could exploit the vulnerability to cause a denial of service

Trust: 2.16

sources: NVD: CVE-2019-9228 // JVNDB: JVNDB-2019-006942 // CNVD: CNVD-2019-32044

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-32044

AFFECTED PRODUCTS

vendor:audiocodesmodel:median 800c-msbrscope:lteversion:f7.20a.252.062

Trust: 1.0

vendor:audiocodesmodel:median 500-msbrscope:gteversion:f7.20a

Trust: 1.0

vendor:audiocodesmodel:median m800b-msbrscope:lteversion:f7.20a.252.062

Trust: 1.0

vendor:audiocodesmodel:median 800c-msbrscope:gteversion:f7.20a

Trust: 1.0

vendor:audiocodesmodel:median 500-msbrscope:lteversion:f7.20a.252.062

Trust: 1.0

vendor:audiocodesmodel:median 500l-msbrscope:gteversion:f7.20a

Trust: 1.0

vendor:audiocodesmodel:median 500l-msbrscope:lteversion:f7.20a.252.062

Trust: 1.0

vendor:audiocodesmodel:median m800b-msbrscope:gteversion:f7.20a

Trust: 1.0

vendor:audiocodesmodel:mediant 500-mbsrscope: - version: -

Trust: 0.8

vendor:audiocodesmodel:mediant 500l-msbrscope: - version: -

Trust: 0.8

vendor:audiocodesmodel:mediant 800c-msbrscope: - version: -

Trust: 0.8

vendor:audiocodesmodel:mediant m800b-msbrscope: - version: -

Trust: 0.8

vendor:audiocodesmodel:mediant 500l-msbr >=f7.20a,<=7.20a.252.062scope: - version: -

Trust: 0.6

vendor:audiocodesmodel:mediant 500-mbsr >=f7.20a,<=7.20a.252.062scope: - version: -

Trust: 0.6

vendor:audiocodesmodel:mediant m800b-msbr >=f7.20a,<=7.20a.252.062scope: - version: -

Trust: 0.6

vendor:audiocodesmodel:mediant 800c-msbr >=f7.20a,<=7.20a.252.062scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2019-32044 // JVNDB: JVNDB-2019-006942 // NVD: CVE-2019-9228

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-9228
value: HIGH

Trust: 1.0

NVD: CVE-2019-9228
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-32044
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201907-1143
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-9228
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-32044
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-9228
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-32044 // JVNDB: JVNDB-2019-006942 // CNNVD: CNNVD-201907-1143 // NVD: CVE-2019-9228

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-399

Trust: 0.8

sources: JVNDB: JVNDB-2019-006942 // NVD: CVE-2019-9228

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201907-1143

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201907-1143

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-006942

PATCH

title:Multi-Service Business Routers (MSBRs)url:https://www.audiocodes.com/solutions-products/products/multi-service-business-routers-msbrs

Trust: 0.8

title:Patches for several AudioCodes product resource management error vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/180689

Trust: 0.6

title:Multiple AudioCodes Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=95139

Trust: 0.6

sources: CNVD: CNVD-2019-32044 // JVNDB: JVNDB-2019-006942 // CNNVD: CNNVD-201907-1143

EXTERNAL IDS

db:NVDid:CVE-2019-9228

Trust: 3.0

db:JVNDBid:JVNDB-2019-006942

Trust: 0.8

db:CNVDid:CNVD-2019-32044

Trust: 0.6

db:CNNVDid:CNNVD-201907-1143

Trust: 0.6

sources: CNVD: CNVD-2019-32044 // JVNDB: JVNDB-2019-006942 // CNNVD: CNNVD-201907-1143 // NVD: CVE-2019-9228

REFERENCES

url:https://www.cirosec.de/fileadmin/1._unternehmen/1.4._unsere_kompetenzen/security_advisory_audiocodes_mediant_family.pdf

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-9228

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-9228

Trust: 0.8

sources: CNVD: CNVD-2019-32044 // JVNDB: JVNDB-2019-006942 // CNNVD: CNNVD-201907-1143 // NVD: CVE-2019-9228

SOURCES

db:CNVDid:CNVD-2019-32044
db:JVNDBid:JVNDB-2019-006942
db:CNNVDid:CNNVD-201907-1143
db:NVDid:CVE-2019-9228

LAST UPDATE DATE

2024-11-23T23:01:48.461000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-32044date:2019-09-19T00:00:00
db:JVNDBid:JVNDB-2019-006942date:2019-07-30T00:00:00
db:CNNVDid:CNNVD-201907-1143date:2020-08-25T00:00:00
db:NVDid:CVE-2019-9228date:2024-11-21T04:51:15.263

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-32044date:2019-09-18T00:00:00
db:JVNDBid:JVNDB-2019-006942date:2019-07-30T00:00:00
db:CNNVDid:CNNVD-201907-1143date:2019-07-19T00:00:00
db:NVDid:CVE-2019-9228date:2019-07-19T23:15:11.280